Apple Acquired Firmware Security Company LegbaCore Last November

legbacoreApple acquired firmware security company LegbaCore in November 2015, according to security researcher Trammell Hudson, who revealed the acquisition in his presentation at the 32C3 conference in December. LegbaCore's goal, according to founder Xeno Kovah, is "to help build systems that are as secure as we know how to make."

In November, Kovah and fellow LegbaCore founder Corey Kallenberg revealed that they had joined Apple as full-time employees. Just a couple days before that, LegbaCore's website announced that it would "not be accepting any new customer engagements", noting that the website would remain up "to serve as a reference for LegbaCore's past work."

LegbaCore had collaborated with Hudson on Thunderstrike 2, the first firmware worm to affect Mac computers. The malware is impossible to remove, resistant to both firmware and software updates. LegbaCore and Hudson had alerted Apple to Thunderstrike 2's vulnerabilities and Apple began work on fixes, issuing one in June 2015.

On Twitter, Kovah said that Apple began discussions with LegbaCore after the consultancy's presentation in summer 2015. It soon became clear to Kovah and Kallenberg that Apple had "some *very* interesting and highly impactful work" that the two could participate in. They were eventually convinced to wind down LegbaCore's existing contracts and begin work at Apple.


While LegbaCore is a security consultancy firm that doesn't own any specific technology, it's likely Apple will use Kovah and Kallenberg's talent and knowledge to help improve firmware and software security in future iterations of Apple's various hardware and software products. LegbaCore's work includes research on Thunderstrike 2, "dead code" for BIOS attacks and more.

(Thanks, Jost!)

Top Rated Comments

(View all)
Avatar
56 months ago
You know where firmware security would be *really* critical?

A car.

Just sayin'.

Of course it matters everywhere else too...
Score: 21 Votes (Like | Disagree)
Avatar
56 months ago
This rocks. If there is one thing Apple can do to distance itself from the competition (Google and Microsoft where your the product or your the product and shared with the NSA) its going all in on giving users privacy and security.

Apple will need an extended focus on this (the security / privacy environment will only get worse) so this is a good sign upper management really gets it. Go Apple - this is how you make sure I get a Mac next time I'm replacing a PC.
Score: 13 Votes (Like | Disagree)
Avatar
56 months ago
I like where this is headed.....

Stay tuned!
Score: 9 Votes (Like | Disagree)
Avatar
56 months ago

This rocks. If there is one thing Apple can do to distance itself from the competition (Google and Microsoft where your the product or your the product and shared with the NSA) its going all in on giving users privacy and security.

Apple will need an extended focus on this (the security / privacy environment will only get worse) so this is a good sign upper management really gets it. Go Apple - this is how you make sure I get a Mac next time I'm replacing a PC.

Plus now they have to worry about the government trying to backdoor their ass for the next few decades. No pun intended.
Score: 8 Votes (Like | Disagree)
Avatar
56 months ago

1. Create exploit
2. Publicize exploit
3. ???
4. Profit

The exploit already exists, they just find it and take advantage of it. Then they let Apple know. Then they tell Apple we will tell you how for a fee. Then profit
if they do nothing they release the exploit. Then no profit.
Score: 7 Votes (Like | Disagree)
Avatar
56 months ago

With that image it makes them look like they're a conglomerate for some jailbreaking organization. I Like it.

No, I think it means Apple is now being run by the Free Masons.
Score: 7 Votes (Like | Disagree)

Top Stories

Leaker: Apple to Stick With Lightning Over USB-C for 'iPhone 12' Before Going Port-Less Next Year

Tuesday May 26, 2020 2:31 am PDT by
Apple will use a Lightning port instead of USB-C in the upcoming "iPhone 12," but it will be the last major series of Apple's flagship phones to do so, with models set to combine wireless charging and a port-less Smart Connector system for data transfer and syncing in the iPhone "13 series" next year. The above claim comes from occasional Apple leaker and Twitter user "Fudge" (@choco_bit),...

Apple Releases macOS Catalina 10.15.5 With Battery Health Management Features, Fix for Finder Freezing

Tuesday May 26, 2020 1:59 pm PDT by
Apple today released macOS Catalina 10.15.5, the fifth update to the macOS Catalina operating system that was released in October 2019. macOS Catalina 10.15.5 comes two months after the launch of macOS Catalina 10.15.4, which introduced Screen Time Communication Limits. macOS Catalina 10.15.5 is a free update that can be downloaded from the Mac App Store using the Update feature in the...

16-Inch MacBook Pro, iPad Pro, and iMac Pro With Mini-LED Displays Again Rumored to Launch in 2021

Tuesday May 26, 2020 5:30 am PDT by
Apple plans to release several higher-end devices with Mini-LED displays in 2021, including a new 12.9-inch iPad Pro in the first quarter, a new 16-inch MacBook Pro in the second quarter, and a new 27-inch iMac in the second half of the year, according to Jeff Pu, an analyst at Chinese research firm GF Securities. This timeframe lines up with one shared by analyst Ming-Chi Kuo, who recently...

Leaker Shares Details on 'iPhone 13' Camera

Wednesday May 27, 2020 4:27 pm PDT by
The next-generation iPhone 12 lineup coming in fall 2020 isn't out yet, but Fudge (@choco_bit), a leaker who sometimes shares information on upcoming Apple devices, today offered up details on what Apple has in store for the 2021 iPhone 13's camera setup. A simple design drawing depicts a device with a four camera array, which Fudge claims will have the following features: 64-megapixel...

Jailbreak Tool 'unc0ver' 5.0 Released With iOS 13.5 Compatibility

Sunday May 24, 2020 3:06 pm PDT by
The team behind the "unc0ver" jailbreaking tool for iOS has released version 5.0.0 of its software that claims to have the ability to jailbreak "every signed iOS version on every device" using a zero-day kernel vulnerability by Pwn20wnd, a renowned iOS hacker. The announcement comes just days after it was announced that the tool would soon launch. The unc0ver website highlights how the tool...

Apple Making It Harder to Avoid Nagging macOS Update Notifications

Thursday May 28, 2020 8:13 am PDT by
With the release of macOS Catalina 10.15.5 and related security updates for macOS Mojave and High Sierra earlier this week, Apple is making it more difficult for users to ignore available software updates and remain on their current operating system versions. Included in the release notes for macOS Catalina 10.15.5 is the following:- Major new releases of macOS are no longer hidden when...

HBO Max Now Available on Apple TV and iOS Devices

Wednesday May 27, 2020 2:42 am PDT by
HBO Max launched today, and is now available on Apple TV, iPhone, and iPad. WarnerMedia's new streaming service, which replaces HBO Now, combines HBO content with shows and films from Warner Bros and Turner TV. The service is available as a native app on the ‌Apple TV‌ HD and ‌Apple TV‌ 4K, but second and third-generation ‌Apple TV‌ owners will need to AirPlay HBO Max content...

First App Using Apple and Google's Exposure Notification API Launches in Switzerland

Tuesday May 26, 2020 3:02 pm PDT by
The first app that takes advantage of the Exposure Notification API developed by Apple and Google has launched in Switzerland, according to a report from the BBC. A team of app developers working on contact tracing app called SwissCovid have rolled out the app in a beta capacity for members of the Swiss army, hospital workers, and civil servants. After the app is tested and approved by MPs,...

Anker Launches $100 24K Gold-Plated USB-C to Lightning Cable

Wednesday May 27, 2020 12:47 pm PDT by
Anker, a brand normally known for its well-made, affordable accessories for Apple devices, has debuted a new $100 24K gold-plated USB-C to Lightning cable. According to Anker, the cable, which is in the PowerLine+ III family, features a "Special Edition Gold Design" that's "bold yet elegant" with the aforementioned gold-plated cable heads and matching braided gold and black cable. The...

Apple Reissuing Numerous iOS App Updates, Potentially Related to Recent 'This App is No Longer Shared' Bug

Sunday May 24, 2020 9:13 pm PDT by
Over the past few hours, a number of MacRumors readers have reported seeing dozens or even hundreds of pending app updates showing in the App Store on their iOS devices, including for many apps that were already recently updated by the users. In many cases, the dates listed on these new app updates extend back as far as ten days. Apple has not shared any information as to why updates for...